Medium severity5.3NVD Advisory· Published Jul 15, 2022· Updated Jun 17, 2026
CVE-2022-25858
CVE-2022-25858
Description
The package terser before 4.8.1, from 5.0.0 and before 5.14.2 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure usage of regular expressions.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
tersernpm | < 4.8.1 | 4.8.1 |
tersernpm | >= 5.0.0, < 5.14.2 | 5.14.2 |
Affected products
3Patches
Vulnerability mechanics
References
7- github.com/terser/terser/commit/a4da7349fdc92c05094f41d33d06d8cd4e90e76bnvdPatchThird Party AdvisoryWEB
- github.com/terser/terser/commit/d8cc5691be980d663c29cc4d5ce67e852d597012nvdPatchThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-2949722nvdExploitPatchThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JS-TERSER-2806366nvdExploitPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-4wf5-vphf-c2xcghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-25858ghsaADVISORY
- github.com/terser/terser/blob/master/lib/compress/evaluate.js%23L135nvdBroken LinkWEB
News mentions
0No linked articles in our index yet.